Key Facts

CERT Polska reports active exploitation of a RouterOS vulnerability chain against internet-accessible devices with SSH enabled, allowing unauthenticated full device control.

Technical Details

The advisory calls the chain “MikroTrick” and says it combines two of six disclosed RouterOS vulnerabilities; affected components include the SSH server and client, bandwidth-test, X.509 handling, and WebFig.

Impact & Mitigation

MikroTik has published fixed releases. Apply the update immediately, limit management services to trusted networks, and review configurations for unknown users, scripts, scheduled tasks, proxies, and tunnels.

Sources

By Allan